This is harmless, memory resident parasitic virus. It hooks INT 9, 13h, 1Ch, 21h, and 28h. The virus writes itself to the end of COM and EXE files. When the file is executed, the virus stores its name, and infects that file on INT 1Ch or INT 28h calls. So the virus infects the file not at the same moment when the file is executed, but with some delay.
Other interrupt vectors the virus uses in its video effect: the virus changes the video mode, pages, cursor and mouse position, and displays the string “1st”.
The virus contains the encrypted text strings:
|Find out the statistics of the threats spreading in your region|